{"slug": "five-things-we-learned-building-scam-detection-into-an-outlook-add-in", "title": "Five things we learned building scam detection into an Outlook add-in", "summary": "A developer behind OutlookDog, an AI-powered Outlook add-in for email scam detection, shared five engineering lessons from a year of building on the Office add-in platform. The team found that users respond to plain-language warnings over protocol terms like SPF failures, and that a read-only add-in incapable of sending, deleting, or moving mail resists prompt injection and malicious-email manipulation. The tool flags spoofed trusted senders even when users safelist them and shows specific red flags to cut false-positive complaints.", "body_md": "*Disclosure: we build OutlookDog, an AI add-in for Outlook — this post is the engineering lessons, not a pitch.*\n\nAfter a year of building email-safety features on the Office add-in platform, here are five lessons that might help anyone working in this space.\n\nUsers don't act on \"SPF fail\" — they act on \"this sender looks like your vendor but isn't.\" We demoted every protocol term to a footnote and warnings started working.\n\nAn add-in that can't send, delete, or move mail can't be tricked into doing any of those things — by a user mistake, a prompt injection, or a malicious email pretending to be a rule. It's also the difference between \"please approve this add-in\" going well or badly with an IT team.\n\nA message that fails identity checks gets warned about even if the user marked that sender safe — the spoof of a trusted sender is exactly the mail the safelist would otherwise wave through.\n\nWe tuned toward warn-and-explain: every flag shows its specific red flags so the user can judge in seconds. False-positive complaints dropped when the *reason* became visible, not when the warnings got rarer.\n\nFor a title company, a closing practice, a property manager — one caught \"updated wiring instructions\" email pays for a decade of any tool. That's the email to design for, not the lottery-scam strawman.\n\nHappy to go deeper on any of these in the comments. We build [OutlookDog](https://outlookdog.com) and launched it on Product Hunt this week.", "url": "https://wpnews.pro/news/five-things-we-learned-building-scam-detection-into-an-outlook-add-in", "canonical_source": "https://dev.to/outlookdog/five-things-we-learned-building-scam-detection-into-an-outlook-add-in-53ie", "published_at": "2026-09-15 16:53:38+00:00", "updated_at": "2026-09-15 17:20:30.053712+00:00", "lang": "en", "topics": ["ai-products", "ai-tools", "ai-agents", "developer-tools", "artificial-intelligence"], "entities": ["OutlookDog", "Outlook", "Office add-in platform", "Product Hunt"], "alternates": {"html": "https://wpnews.pro/news/five-things-we-learned-building-scam-detection-into-an-outlook-add-in", "markdown": "https://wpnews.pro/news/five-things-we-learned-building-scam-detection-into-an-outlook-add-in.md", "text": "https://wpnews.pro/news/five-things-we-learned-building-scam-detection-into-an-outlook-add-in.txt", "jsonld": "https://wpnews.pro/news/five-things-we-learned-building-scam-detection-into-an-outlook-add-in.jsonld"}}